CVE-2018-20733
Published Jan 17, 2019BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
Vendor/product archive
3 CVEs tagged to sas / web_infrastructure_platform — 1 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.